Explains how IP source guard features secure wireless networks by preventing unauthorized packets based on IP/MAC bindings.
A set of IP source guard features are Layer 2 security mechanisms that
-
prevent the controller from forwarding packets with source IP addresses unknown to the wireless controller
-
require explicit configuration per WLAN and are not enabled by default, and
-
maintain an IP/MAC binding table to track and authorize valid wireless clients.
It supports both IPv4 and IPv6 wireless clients. The IPSG feature prevents the wireless controller from forwarding packets with unknown source IP addresses. This security feature is disabled by default. You must configure it explicitly for each WLAN. When you enable this feature, all wireless clients on the WLAN inherit the security setting.
Using the IP/MAC binding table, the wireless controller keeps track of IP and MAC address binding information for all wireless clients. The wireless controller collects binding information as part of the IP learning process. When this feature is enabled on a WLAN, the wireless controller forwards incoming packets from wireless clients only if a matching binding table entry exists for the source IP and MAC address combination. If the entry does not exist, the controller drops the packets.